0x5c16cbd65c16…5c16cbd9

ConfirmedSecurity—80 sat/vB

Bitget's $388M Hack Traced to Third-Party Security Flaw, CEO Says

Bitget CEO Gracy Chen says the $388M Sept. 24 exploit came from a third-party security flaw that yielded high-level internal credentials; cold wallets were unaffected.

Outputs

  1. Bitget attributes its $388 million exploit to a vulnerability in a third-party security product.

  2. The attack occurred on Sept. 24 and initially affected roughly $352 million before the figure was revised to $388 million.

  3. CEO Gracy Chen said the attacker obtained "high-level internal credentials" but did not compromise private keys or cold wallets.

  4. Mandiant and SlowMist are conducting an independent forensic investigation; a North Korea attribution remains unconfirmed.

  5. Bitget has not disclosed how much stolen crypto has been recovered or frozen.

Bitget CEO Gracy Chen said the exchange's $388 million exploit stemmed from a vulnerability in a third-party security product, which allowed the attacker to obtain "high-level internal credentials" and issue fraudulent withdrawal commands.

Chen disclosed the root cause in comments to Cointelegraph. Bitget's private keys were not compromised, and its cold wallets were not affected, she said. The attack vector ran through a supplier's software rather than the exchange's own key management — a distinction that shapes both liability and remediation.

The incident occurred on Sept. 24, when Bitget detected unauthorized transfers from several of its hot wallets and temporarily suspended withdrawals. The exchange initially estimated that roughly $352 million in assets had been affected. The revised $388 million figure is the latest confirmed total.

What has Bitget changed since the breach?

Bitget says it has fixed the security flaw and tightened its withdrawal controls. The measures include:

  • Restricting internal access to sensitive systems
  • Adding independent verification for withdrawals
  • Increasing monitoring for unusual activity

The exchange has not disclosed how much of the stolen crypto has been recovered or frozen. Chen said some assets have been frozen with help from other industry participants, but Bitget will publish a total only after verifying the amounts.

Where did the stolen funds go?

Bitget previously called on THORChain, a cross-chain swapping protocol, to refuse services to addresses linked to the attack. The exchange says it is not asking THORChain to halt its network outright as it tries to prevent the stolen assets from moving.

THORChain has said it cannot selectively blacklist individual addresses. Chen struck a conciliatory tone on the protocol's technical limits.

"We understand that THORChain operates as a decentralized protocol and has said that it cannot selectively blacklist individual addresses. We respect the technical constraints of different networks and are not asking any protocol to take actions that are not technically possible," Chen said.

The standoff illustrates a recurring operational problem for centralized exchanges: once laundered through cross-chain infrastructure, stolen funds move beyond any single operator's ability to freeze them, leaving recovery dependent on voluntary cooperation from counterparties.

Is North Korea still a suspect?

Chen also addressed Bitget's earlier suggestion that North Korea may have been behind the attack. That attribution remains unconfirmed.

"What was shared previously was based on preliminary indicators identified during the investigation," Chen said.

"Those indicators are still being assessed. Mandiant and SlowMist are supporting the independent forensic investigation, and that work is ongoing. We will share further findings as they are verified," she added.

The engagement of Mandiant, a Google-owned threat-intelligence firm, alongside blockchain-forensics specialist SlowMist signals a formal attribution process rather than an informal read. For an exchange of Bitget's scale, a confirmed state-sponsored attribution would carry regulatory and insurance implications.

What comes next?

Two open items will define the story's trajectory: the verified recovery total, which Bitget says it will release after confirmation, and the forensic findings from Mandiant and SlowMist on attribution. Until both land, the effective loss from the Sept. 24 incident — somewhere between zero and $388 million — remains the exchange's most material unresolved exposure.

via s3.tradingview.com (Original)

More from Tom Whitfield

Tom Whitfield

Show full bio

News editor covering media and advertising at Mempool Brief.

419 articles